Re: [WebDNA] path traversal
This WebDNA talk-list message is from 2020
It keeps the original formatting.
numero = 115088
interpreted = N
texte = 2717--Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7Content-Transfer-Encoding: quoted-printableContent-Type: text/plain;charset=utf-8Good on you. As long as WSC doesn=E2=80=99t munge the old commerce tags =/ contexts (no guarantees that they are not already messed with), you =should=20be good for awhile. That old commerce system is one of the main reasons =why I (and many) fell in love with WebDNA=E2=80=A6 but it hasn=E2=80=99t =been improved on nor supported since 2012 or so.Donovan> On Apr 14, 2020, at 11:59 AM, talk@webdna.us wrote:>=20> It=E2=80=99s actually the oldest running eShop for computer hardware =in Israel launched in 1997 with WebCatalog on Mac OS (PowerPC)> and 2-3 years ago moved to CentOS and WebDNA enterprise.> The WebDNA runs great will all the ^ and all the other weird stuff and =the site is super solid and fast for decades> And also new code is added all the time for the last 22 years and now =this issue also solved>=20> No reason to change nothing. Same URLs for 22 years is something =Google adore.>=20> Yours,>=20> Yariv>=20>=20>> On 14 Apr 2020, at 12:19, talk@webdna.us wrote:>>=20>> As far as I know the old (but awesome) e-commerce system is no longer =supported.=20>>=20>> Every commerce context for that old e-commerce system (orderfile, =addlitems, etc) had path parameter options... (so, for example ==E2=80=98file=3D^=E2=80=99).>>=20>> =E2=80=98^=E2=80=99 symbol is the path to the globals directory. =(Which is also, I believe, said to be unsupported)=20>>=20>> I=E2=80=99d suggest finding a new solution.. but if you are sticking =with ancient technology, find a copy of the older docs. Good luck=20>>=20>>=20>>=20>> D. Brooke Mobile>>=20>>> On Apr 14, 2020, at 2:55 AM, talk@webdna.us wrote:>>>=20>>> =EF=BB=BFA security friend told me about "path traversal=E2=80=9D=20>>> https://portswigger.net/web-security/file-path-traversal>>>=20>>> and told me that the idea that the =E2=80=9CShoppingCarts=E2=80=9D =folder is located usually under a website folder is not a good practice.>>> How do i move the creation of files from the directory under the =website forlder to be under the Globals so it=E2=80=99ll be protected =from such kind of attack ?>>>=20>>> I made such directory elsewhere but didn=E2=80=99t know how to make =WebDNA use it ?>>>=20>>> I use CentOS 7 and=20>>>=20>>> Yours,>>>=20>>> Yariv--------------------------------------------------------->>> This message is sent to you because you are subscribed to>>> the mailing list talk@webdna.us>>> To unsubscribe, E-mail to: talk-leave@webdna.us>>> archives: http://www.webdna.us/page.dna?numero=3D55>>> Bug Reporting: support@webdna.us>>=20>> --------------------------------------------------------->> This message is sent to you because you are subscribed to>> the mailing list talk@webdna.us>> To unsubscribe, E-mail to: talk-leave@webdna.us>> archives: http://www.webdna.us/page.dna?numero=3D55>> Bug Reporting: support@webdna.us>=20> ---------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list talk@webdna.us> To unsubscribe, E-mail to: talk-leave@webdna.us> archives: http://www.webdna.us/page.dna?numero=3D55> Bug Reporting: support@webdna.usDonovan BrookeOwner - EUCA(608) 770-3822355 E State St. APT 8Iola, WI 54945--Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7Content-Transfer-Encoding: quoted-printableContent-Type: text/html;charset=utf-8
Good =on you. As long as WSC doesn=E2=80=99t munge the old commerce tags / =contexts (no guarantees that they are not already messed with), you =should
be good for awhile. That old commerce system =is one of the main reasons why I (and many) fell in love with WebDNA=E2=80==A6 but it hasn=E2=80=99t been improved on nor supported since 2012 or =so.
Donovan
It=E2=80=99s actually the oldest running eShop for computer =hardware in Israel launched in 1997 with WebCatalog on Mac OS =(PowerPC)
and 2-3 years ago moved to CentOS and WebDNA =enterprise.
The WebDNA runs great will all the ^ and all =the other weird stuff and the site is super solid and fast for =decades
And also new code is added all the time for the =last 22 years and now this issue also solved
No reason to change nothing. Same URLs for 22 years is =something Google adore.
Yours,
Yariv
On 14 Apr 2020, at =12:19, talk@webdna.us =wrote:
As far as I know the old (but =awesome) e-commerce system is no longer supported.
Every commerce context for that old e-commerce system =(orderfile, addlitems, etc) had path parameter options... (so, for =example =E2=80=98file=3D^=E2=80=99).
=E2=80=98=^=E2=80=99 symbol is the path to the globals directory. (Which is also, =I believe, said to be unsupported)
I=E2=80=99=d suggest finding a new solution.. but if you are sticking with ancient =technology, find a copy of the older docs. Good luck
D. Brooke Mobile
On Apr =14, 2020, at 2:55 AM, talk@webdna.us wrote:
=EF=BB=BF=A security friend told me about "path traversal=E2=80=9D
https://portswigger.net/web-security/file-path-traversal
and told me that the idea that the ==E2=80=9CShoppingCarts=E2=80=9D folder is located usually under a =website folder is not a good practice.
How do i move the =creation of files from the directory under the website forlder to be =under the Globals so it=E2=80=99ll be protected from such kind of attack =?
I made such directory elsewhere but =didn=E2=80=99t know how to make WebDNA use it ?
I use CentOS 7 and
Yours,
Yariv---------------------------------------------------------<=br class=3D"">This message is sent to you because you are subscribed =to
the mailing list talk@webdna.us
To =unsubscribe, E-mail to: talk-leave@webdna.us
archives: =http://www.webdna.us/page.dna?numero=3D55
Bug Reporting: =support@webdna.us
---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list talk@webdna.us
To unsubscribe, E-mail to: =talk-leave@webdna.us
archives: http://www.webdna.us/page.dna?numero=3D55
Bug= Reporting: support@webdna.us
---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list
talk@webdna.usTo unsubscribe, E-mail to: =
talk-leave@webdna.usarchives:
http://www.webdna.us/page.dna?numero=3D55Bug= Reporting:
support@webdna.us
Donovan Brooke
Owner - =EUCA
(608) 770-3822
355 E State St. APT 8
Iola, WI =54945
=---------------------------------------------------------This message is sent to you because you are subscribed tothe mailing list talk@webdna.usTo unsubscribe, E-mail to: talk-leave@webdna.usarchives: http://www.webdna.us/page.dna?numero=3D55Bug Reporting: support@webdna.us--Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7--.
Associated Messages, from the most recent to the oldest:
2717--Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7Content-Transfer-Encoding: quoted-printableContent-Type: text/plain;charset=utf-8Good on you. As long as WSC doesn=E2=80=99t munge the old commerce tags =/ contexts (no guarantees that they are not already messed with), you =should=20be good for awhile. That old commerce system is one of the main reasons =why I (and many) fell in love with WebDNA=E2=80=A6 but it hasn=E2=80=99t =been improved on nor supported since 2012 or so.Donovan> On Apr 14, 2020, at 11:59 AM, talk@webdna.us wrote:>=20> It=E2=80=99s actually the oldest running eShop for computer hardware =in Israel launched in 1997 with WebCatalog on Mac OS (PowerPC)> and 2-3 years ago moved to CentOS and WebDNA enterprise.> The WebDNA runs great will all the ^ and all the other weird stuff and =the site is super solid and fast for decades> And also new code is added all the time for the last 22 years and now =this issue also solved>=20> No reason to change nothing. Same URLs for 22 years is something =Google adore.>=20> Yours,>=20> Yariv>=20>=20>> On 14 Apr 2020, at 12:19, talk@webdna.us wrote:>>=20>> As far as I know the old (but awesome) e-commerce system is no longer =supported.=20>>=20>> Every commerce context for that old e-commerce system (orderfile, =addlitems, etc) had path parameter options... (so, for example ==E2=80=98file=3D^=E2=80=99).>>=20>> =E2=80=98^=E2=80=99 symbol is the path to the globals directory. =(Which is also, I believe, said to be unsupported)=20>>=20>> I=E2=80=99d suggest finding a new solution.. but if you are sticking =with ancient technology, find a copy of the older docs. Good luck=20>>=20>>=20>>=20>> D. Brooke Mobile>>=20>>> On Apr 14, 2020, at 2:55 AM, talk@webdna.us wrote:>>>=20>>> =EF=BB=BFA security friend told me about "path traversal=E2=80=9D=20>>> https://portswigger.net/web-security/file-path-traversal>>>=20>>> and told me that the idea that the =E2=80=9CShoppingCarts=E2=80=9D =folder is located usually under a website folder is not a good practice.>>> How do i move the creation of files from the directory under the =website forlder to be under the Globals so it=E2=80=99ll be protected =from such kind of attack ?>>>=20>>> I made such directory elsewhere but didn=E2=80=99t know how to make =WebDNA use it ?>>>=20>>> I use CentOS 7 and=20>>>=20>>> Yours,>>>=20>>> Yariv--------------------------------------------------------->>> This message is sent to you because you are subscribed to>>> the mailing list talk@webdna.us>>> To unsubscribe, E-mail to: talk-leave@webdna.us>>> archives: http://www.webdna.us/page.dna?numero=3D55>>> Bug Reporting: support@webdna.us>>=20>> --------------------------------------------------------->> This message is sent to you because you are subscribed to>> the mailing list talk@webdna.us>> To unsubscribe, E-mail to: talk-leave@webdna.us>> archives: http://www.webdna.us/page.dna?numero=3D55>> Bug Reporting: support@webdna.us>=20> ---------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list talk@webdna.us> To unsubscribe, E-mail to: talk-leave@webdna.us> archives: http://www.webdna.us/page.dna?numero=3D55> Bug Reporting: support@webdna.usDonovan BrookeOwner - EUCA(608) 770-3822355 E State St. APT 8Iola, WI 54945--Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7Content-Transfer-Encoding: quoted-printableContent-Type: text/html;charset=utf-8
Good =on you. As long as WSC doesn=E2=80=99t munge the old commerce tags / =contexts (no guarantees that they are not already messed with), you =should
be good for awhile. That old commerce system =is one of the main reasons why I (and many) fell in love with WebDNA=E2=80==A6 but it hasn=E2=80=99t been improved on nor supported since 2012 or =so.
Donovan
It=E2=80=99s actually the oldest running eShop for computer =hardware in Israel launched in 1997 with WebCatalog on Mac OS =(PowerPC)
and 2-3 years ago moved to CentOS and WebDNA =enterprise.
The WebDNA runs great will all the ^ and all =the other weird stuff and the site is super solid and fast for =decades
And also new code is added all the time for the =last 22 years and now this issue also solved
No reason to change nothing. Same URLs for 22 years is =something Google adore.
Yours,
Yariv
On 14 Apr 2020, at =12:19, talk@webdna.us =wrote:
As far as I know the old (but =awesome) e-commerce system is no longer supported.
Every commerce context for that old e-commerce system =(orderfile, addlitems, etc) had path parameter options... (so, for =example =E2=80=98file=3D^=E2=80=99).
=E2=80=98=^=E2=80=99 symbol is the path to the globals directory. (Which is also, =I believe, said to be unsupported)
I=E2=80=99=d suggest finding a new solution.. but if you are sticking with ancient =technology, find a copy of the older docs. Good luck
D. Brooke Mobile
On Apr =14, 2020, at 2:55 AM, talk@webdna.us wrote:
=EF=BB=BF=A security friend told me about "path traversal=E2=80=9D
https://portswigger.net/web-security/file-path-traversal
and told me that the idea that the ==E2=80=9CShoppingCarts=E2=80=9D folder is located usually under a =website folder is not a good practice.
How do i move the =creation of files from the directory under the website forlder to be =under the Globals so it=E2=80=99ll be protected from such kind of attack =?
I made such directory elsewhere but =didn=E2=80=99t know how to make WebDNA use it ?
I use CentOS 7 and
Yours,
Yariv---------------------------------------------------------<=br class=3D"">This message is sent to you because you are subscribed =to
the mailing list talk@webdna.us
To =unsubscribe, E-mail to: talk-leave@webdna.us
archives: =http://www.webdna.us/page.dna?numero=3D55
Bug Reporting: =support@webdna.us
---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list talk@webdna.us
To unsubscribe, E-mail to: =talk-leave@webdna.us
archives: http://www.webdna.us/page.dna?numero=3D55
Bug= Reporting: support@webdna.us
---------------------------------------------------------
This message is sent to you because you are subscribed to
the mailing list
talk@webdna.usTo unsubscribe, E-mail to: =
talk-leave@webdna.usarchives:
http://www.webdna.us/page.dna?numero=3D55Bug= Reporting:
support@webdna.us
Donovan Brooke
Owner - =EUCA
(608) 770-3822
355 E State St. APT 8
Iola, WI =54945
=---------------------------------------------------------This message is sent to you because you are subscribed tothe mailing list talk@webdna.usTo unsubscribe, E-mail to: talk-leave@webdna.usarchives: http://www.webdna.us/page.dna?numero=3D55Bug Reporting: support@webdna.us--Apple-Mail=_31622E4A-B54D-4216-8584-7D7199C187A7--.
Donovan Brooke
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
New syntax feedback for 4.0 (2000)
# fields limited? (1997)
WebCat2 - Getting to the browser's username/password data (1997)
Database flushing does not work any more... (2000)
Initiating NewCart (1997)
WebSTAR 2.1 freezes my Mac (1997)
Can WebCatalog.debug solve my problem? (2000)
Part Html part WebDNA (1997)
take me off mailing list please (2001)
Migrating to NT (1997)
Forumulas.db & Variables (2002)
Database Path (1998)
Bug Report, maybe (1997)
[SHOWIF AND/OR] (1997)
syntax question, not in online refernce (1997)
Why is [authenticate] not recognizing [username] on all sitedirectories? (2000)
[WebDNA] WebDNA Sciprt for Zipping files? (2012)
Extended [ConvertChars] (1997)
HomePage Caution (1997)
Multiple cart additions (1997)